PT-2017-7408 · Puppet · Puppet Enterprise
Published
2017-12-11
·
Updated
2022-01-24
·
CVE-2015-8470
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Puppet Enterprise versions 3.7.x through 3.8.x and 2015.2.x
Description
The issue is related to the console in Puppet Enterprise not setting the secure flag for the
JSESSIONID cookie in an HTTPS session. This makes it easier for remote attackers to capture the cookie by intercepting its transmission within an HTTP session.Recommendations
For Puppet Enterprise versions 3.7.x, 3.8.x, and 2015.2.x, consider updating the configuration to set the secure flag for the
JSESSIONID cookie in HTTPS sessions to prevent interception.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Puppet Enterprise